Data processing and subcontractors (DPA)
Last updated: September 05, 2026
This page describes, in plain language, the data Garatools processes to provide the service, how long it is kept, and the companies that have access to it. It meets the transparency requirements of the GDPR (regulation (EU) 2016/679).
Data controller
The data controller is the publisher of the service, to whom you have entrusted your data. Their contact details appear in the legal notice.
Subcontractor on behalf of garages
Garatools acts as a subcontractor (article 28 of the GDPR) for the customer and vehicle data that garages enter. Each garage is responsible for its own processing and for its customers' consent. A data processing agreement (DPA) governs this relationship.
Categories of data processed
Garage account (name, email, hashed password); garage information (name, email); customer accounts and vehicles entered by the garage (name, email, plate, make, model, status); notification history sent; activity log. Passwords are stored hashed, never in clear text.
Purposes of processing
To provide the Garatools workshop: registering vehicles, tracking statuses, sending availability notifications to the end customer, billing the subscription. No data is used for marketing or sold.
Retention period
Garage and customer data is kept as long as the account is active. On account deletion, all associated data is erased (soft delete then erasure in the database). Expired sessions and activity logs older than 12 months are purged automatically.
Your rights
You have the right to access, rectify, erase, restrict, object to and port your data. To exercise it, contact the publisher at the address in the legal notice. Account deletion from settings immediately erases all your data.
Subcontractors
The service relies on the following companies, to which some data is transmitted according to their role. Their locations are indicated for information only.
- Vercel Inc. — Application hosting — European Union (cdg1 region, Paris)
- Neon Inc. — Database hosting — European Union
- Brevo (Sendinblue SAS) — Sending notification emails — France
- Stripe Payments Europe, Ltd. — Subscription payments — Ireland
Security
Data is transmitted over HTTPS, passwords are hashed, access is filtered by garage (multi-tenant isolation), and session tokens are never stored in clear text. Payments are entirely handled by Stripe, a PCI-DSS certified processor.
Contact
For any question about the processing of your data, write to the contact address in the legal notice.